03:49 PM

7 Tools To Tighten Healthcare Data Security

Most of the largest healthcare data security and privacy breaches have involved lost or stolen mobile computing devices. Consider these tools and tips for protecting patient data and managing breaches.
1 of 7

Smartphones, tablets, and other mobile devices can help facilitate better communication and more extensive patient-caregiver interaction. But they're also easy to lose and more challenging for IT departments to manage.

In fact, mobile devices--including laptop computers, flash drives, and other portable gear--have been involved with some of the largest Health Insurance Portability and Accountability Act (HIPAA) breaches to date affecting 500 or more individuals, according to the Dept. of Health and Human Services, which tracks those incidents on a data breach reporting website that healthcare players have dubbed, the Hall of Shame.

At the same time, healthcare providers have a lot more to lose besides their reputations when it comes to HIPAA violations: Under the HITECH Act, HHS now can impose penalties of as much as $1.5 million annually per organization--per hospital or doc practice--for violating HIPAA privacy rules.

Unfortunately, many of the largest data and security incidents--as well as large HIPAA breaches involving paper documents--have been caused by human error, according to HHS. But besides improving training of staff about best practices for protecting patient data privacy and security--and not allowing any sensitive data to be stored on mobile devices themselves--healthcare organizations can tap an array of vendors' software and other products to safeguard protected health information. Here's a look at some of those tools.

1 of 7
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-09
Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.

Published: 2015-10-09
The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.

Published: 2015-10-09
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

Published: 2015-10-09
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

Published: 2015-10-09
The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.